← Back

Ghostscript

ghostscript

Vendor: Artifex • 129 CVEs

CVEs (129)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Artifex
1Ghostscript
Jun 17, 2026
Sep 22, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
1Artifex
1Ghostscript
Jun 17, 2026
Sep 22, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.
1Artifex
1Ghostscript
Jun 17, 2026
Sep 22, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
1Artifex
1Ghostscript
Jun 17, 2026
May 23, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
1Artifex
1Ghostscript
Jun 17, 2026
Apr 26, 2025
N/A· v4
4.5 MEDIUM· v3
N/A· v2
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.
1Artifex
1Ghostscript
Jun 17, 2026
Mar 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.
3Artifex
DebianSuse
5Debian Linux
GhostscriptLinux Enterprise High Performance Computing+2 more
Jun 17, 2026
Nov 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
3Artifex
DebianSuse
5Debian Linux
GhostscriptLinux Enterprise High Performance Computing+2 more
Jun 17, 2026
Nov 10, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
1Artifex
1Ghostscript
Jun 17, 2026
Nov 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.
3Artifex
DebianSuse
5Debian Linux
GhostscriptLinux Enterprise High Performance Computing+2 more
Jun 17, 2026
Nov 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traver...Show more
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.Show less
2Artifex
Debian
2Debian Linux
Ghostscript
Jun 17, 2026
Nov 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).
3Artifex
DebianSuse
5Debian Linux
GhostscriptLinux Enterprise High Performance Computing+2 more
Jun 17, 2026
Nov 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the D...Show more
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.Show less